Back to Guides
Guide16 September 2026

EU AI Act: What Every Developer and Business Must Know

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the EU AI Act and who does it apply to?
  3. How does the Act classify AI risk?
  4. Which AI practices are prohibited today?
  5. What counts as a high - risk AI system?
  6. What obligations do high - risk AI providers face?
  7. How are general - purpose AI models regulated?
  8. When do transparency duties apply?
  9. What is the implementation timetable?
  10. How is the Act enforced and what are the penalties?
  11. Are there any exemptions?
  12. How does the EU AI Act affect non - EU companies?
  13. What steps should developers take today?
  14. Where can I find more detailed guidance?

Key takeaways

What is the EU AI Act and who does it apply to?

The EU AI Act is a Regulation that applies automatically across all EU member states, so no national transposition is required. It covers any AI system placed on the EU market, put into service, or whose output is used in the EU, even if the provider is located outside the Union.

How does the Act classify AI risk?

The Act defines four risk tiers. Unacceptable - risk AI is banned outright. High - risk AI must undergo a full conformity assessment, maintain technical documentation, and implement post - market monitoring. Limited - risk AI (transparency) requires a clear notice that users are interacting with AI or that content is AI - generated. Minimal - risk AI has no specific obligations beyond general AI - literacy duties.

Which AI practices are prohibited today?

From 2 Feb 2025 the following practices are illegal and subject to the highest fines:

What counts as a high - risk AI system?

Annex III lists use - cases that automatically trigger high - risk status, such as:

What obligations do high - risk AI providers face?

High - risk providers must:

How are general - purpose AI models regulated?

General - purpose AI (GPAI) models are defined as large - scale models capable of many tasks. Baseline duties (effective 2 Aug 2025) require:

When do transparency duties apply?

Article 50 introduces transparency duties on 2 Aug 2026. Providers must:

What is the implementation timetable?

DateMilestone
1 Aug 2024Regulation enters into force, AI Office and AI Board created
2 Feb 2025Prohibited practices and AI - literacy duties become enforceable
2 Aug 2025Baseline obligations for GPAI models apply
2 Aug 2026General application of the Act; transparency duties enforceable
2 Dec 2027High - risk Annex III obligations for stand - alone systems become mandatory
2 Aug 2028High - risk Annex I obligations for AI as safety component of regulated products become mandatory

How is the Act enforced and what are the penalties?

National market - surveillance authorities supervise providers and may delegate conformity assessments to notified bodies. The European AI Office coordinates EU - wide enforcement, especially for GPAI models. Penalties are tiered:

Are there any exemptions?

Yes. The Act does not cover military and defence AI, pure research without market application, or personal non - professional use of AI systems.

How does the EU AI Act affect non - EU companies?

Because the regulation applies to any AI output used in the EU, non - EU providers must assess whether their systems fall into any risk tier and implement the corresponding obligations. Failure to do so can lead to significant fines and market restrictions.

What steps should developers take today?

  1. Map your AI portfolio - Identify which systems are potentially high - risk, limited - risk or GPAI.
  2. Perform a gap analysis - Compare current practices against the obligations listed in Articles 8 - 21 (high - risk) and Article 50 (transparency).
  3. Create or update technical documentation - Include data - governance, risk - management, and human - oversight procedures.
  4. Set up a conformity - assessment process - Engage a notified body early if you have high - risk AI.
  5. Implement transparency mechanisms - Add clear UI notices and machine - readable labels for synthetic media.
  6. Monitor the AI Office and national authorities - Stay informed about guidance, especially for GPAI systemic - risk thresholds.

Where can I find more detailed guidance?

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary